CVE-2020-15487
Re:Desk versión 2.3, contiene una vulnerabilidad de inyección SQL ciega no autenticada en la función getBaseCriteria() en el archivo protected/models/Ticket.php. Al modificar el parámetro GET de la carpeta, es posible ejecutar sentencias SQL arbitrarias por medio de una URL diseñada. La ejecución de comandos remotos no autenticados es posible usando esta inyección SQL para actualizar determinados valores de la base de datos, que luego son ejecutados por una función eval() de bizRule en el archivo yii/framework/web/auth/CAuthManager.php. La omisión de autorización resultante también es posible, recuperando o modificando hashes de contraseña y tokens de restablecimiento de contraseña, permitiendo obtener privilegios administrativos
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.69%
- Percentil entre todas las CVEs puntuadas: 89
- Fecha de la puntuación: 10/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-89
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-15487",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-09-30T18:15:22.273",
"references": [
{
"url": "https://labs.f-secure.com/advisories/redesk-v2-3-multiple-issues/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.re-desk.com/download-help-desk-software.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://labs.f-secure.com/advisories/redesk-v2-3-multiple-issues/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.re-desk.com/download-help-desk-software.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protected/models/Ticket.php file. By modifying the folder GET parameter, it is possible to execute arbitrary SQL statements via a crafted URL. Unauthenticated remote command execution is possible by using this SQL injection to update certain database values, which are then executed by a bizRule eval() function in the yii/framework/web/auth/CAuthManager.php file. Resultant authorization bypass is also possible, by recovering or modifying password hashes and password reset tokens, allowing for administrative privileges to be obtained."
},
{
"lang": "es",
"value": "Re:Desk versión 2.3, contiene una vulnerabilidad de inyección SQL ciega no autenticada en la función getBaseCriteria() en el archivo protected/models/Ticket.php. Al modificar el parámetro GET de la carpeta, es posible ejecutar sentencias SQL arbitrarias por medio de una URL diseñada. La ejecución de comandos remotos no autenticados es posible usando esta inyección SQL para actualizar determinados valores de la base de datos, que luego son ejecutados por una función eval() de bizRule en el archivo yii/framework/web/auth/CAuthManager.php. La omisión de autorización resultante también es posible, recuperando o modificando hashes de contraseña y tokens de restablecimiento de contraseña, permitiendo obtener privilegios administrativos"
}
],
"lastModified": "2026-06-17T02:56:43.730",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:re-desk:re\\:desk:2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34C4228B-7583-4BC3-A0D1-A5E60AF4E874"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}